CSIDB logo
Incident

AT&T

Incident posture

Attack window
2024
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 12:05

Linked entities

Victim
AT&T
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

In 2024, AT&T suffered a Snowflake cloud breach, paying a reported $370K ransom to delete call records of over 100 million users.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In mid-2024, AT&T disclosed that a significant cybersecurity incident had affected its Snowflake cloud environment, resulting in the exposure of call records belonging to more than 100 million users. The incident occurred within the broader wave of cloud-targeted breaches that affected multiple organizations leveraging the Snowflake data platform, but the scale of the AT&T exposure made it one of the most prominent incidents associated with that campaign. The breach specifically involved a cloud-based data repository used by AT&T to store customer call records, and the unauthorized access to this environment enabled the threat actors to obtain a substantial volume of telecommunications metadata. Reports indicated that the attackers targeted the cloud environment through compromised credentials, exploiting access that had not been adequately secured, which allowed them to extract sensitive data from AT&T's Snowflake instance.

Following the discovery of the unauthorized access, AT&T engaged with the threat actors who had obtained the records, and according to published reports, the company ultimately paid a ransom reported to be approximately $370,000 in exchange for the deletion of the stolen call records. The decision to pay the ransom was made in an effort to mitigate the potential harm to the more than 100 million affected users whose call records had been compromised in the breach. The exposed data primarily consisted of call metadata, including information about phone calls and text messages, rather than the content of the communications themselves, but the volume and sensitivity of the metadata raised significant privacy concerns. The incident underscored the risks associated with storing large volumes of customer telecommunications data in cloud environments that may be vulnerable to credential-based attacks.

The impact of the AT&T breach extended beyond the immediate privacy concerns for affected customers, as it also raised broader questions about the security of cloud-based data storage and the responsibility of organizations to protect customer information held within third-party platforms. The fact that the breach involved a major telecommunications provider with a customer base numbering in the hundreds of millions amplified the potential consequences, as the compromised call records could be used for targeted phishing, social engineering, or other malicious activities. AT&T's reported payment of the ransom in exchange for the deletion of the data represented one of the more notable responses to a ransomware or extortion-related incident in 2024, though the breach itself was characterized as part of a wider pattern of cloud environment compromises that affected multiple companies during that period. The incident highlighted the ongoing challenges faced by organizations in securing cloud-based data repositories against sophisticated threat actors who have increasingly targeted these environments.

Sources

Sources available to members: 1 source.

CSIDB